Legal

Privacy policy

Last updated: 3 February 2026

§ 1

Who is the controller

Chaotic Events Ltd (trading as Curated Chaos) is the data controller for the personal data described in this policy. Registered address: Canopy, 41 King Street, Leicester, LE1 6RN. Data contact: data@curated-chaos.co.uk.

§ 2

What data we collect

Account data — email, name, profile picture (from your Google account), role (brand / creator / admin).

Brand data — company name, sector, website, target audience, brand guidelines (including any files you upload), goals, subscription status and Stripe customer/subscription IDs.

Creator data — bio, specialisms, location, availability, portfolio (media and links you upload), audience stats you disclose (platform, follower counts, demographics), vetting status, quality and reliability scores, earnings.

Campaign and placement data — briefs, deliverables, drafts, revisions, approvals, ratings, commercial usage rights, outcome metrics.

Payment data — handled by Stripe. We store the Stripe customer and subscription IDs and payment status only; we do not store card numbers.

Technical data — IP address, browser info, session cookie, product analytics (PostHog) that help us understand feature usage. See our Cookies Policy.

Communications — emails you send us, forms you submit (e.g. the free Curated Health Score audit).

§ 3

Why we process it, and our legal bases

To provide the service — creating your account, matching, delivery, invoicing. Legal basis: contract.

Payments — Stripe processes payments on our behalf. Legal basis: contract.

Curated Health Score, matching engine, reliability/quality scoring — we compute these from campaign outcomes to make future matching smarter. Legal basis: legitimate interest (running a fair marketplace) with the ability to opt out of profiling by contacting us.

Product analytics — to understand how the platform is used. Legal basis: consent (via the cookie banner where required).

Transactional emails (welcome, vetting result, match confirmed, payment failed) — sent to keep you informed of contract-critical events. Legal basis: contract and legitimate interest.

Marketing emails — sent only if you opt in. Legal basis: consent. You can unsubscribe from every marketing email.

§ 4

Who we share data with

Sub-processors we use:

  • Google (OAuth) — sign-in identity.
  • Stripe — payments and billing portal.
  • MongoDB Atlas / Emergent Hosting — cloud storage of application data.
  • Emergent Object Storage — file uploads (brand guidelines, portfolios, placement assets).
  • Resend or SendGrid — transactional email delivery.
  • PostHog — product analytics.

We share the minimum data needed for each sub-processor to do its job. We do not sell personal data.

Brands see creators and creators see brands only when there is an active campaign, placement or match between them. Brand access to the roster is gated by an active subscription.

We may disclose data to comply with legal obligations (courts, regulators) or to protect our rights and safety.

§ 5

International transfers

Some of our sub-processors (e.g. Stripe, Google, PostHog) may process data outside the UK/EEA. Where required, we rely on the UK International Data Transfer Addendum or EU Standard Contractual Clauses to protect your data.

§ 6

How long we keep it

Active accounts: for the duration of your use of the platform.

After account closure: we retain financial records for 7 years to comply with UK tax law; other personal data is deleted or anonymised within 90 days unless we need it for legal claims.

Campaign outcome data may be retained in an anonymised, aggregated form to improve matching. Individuals cannot be re-identified.

§ 7

Your rights

Under UK GDPR you have the right to:

  • Access the personal data we hold about you
  • Correct data that is wrong
  • Ask us to delete data (right to erasure)
  • Restrict or object to certain processing
  • Data portability — receive a copy of data you gave us in a machine-readable format
  • Withdraw consent where processing is based on consent
  • Complain to the UK Information Commissioner's Office at ico.org.uk

To exercise any of these, email data@curated-chaos.co.uk. We'll respond within one month.

§ 8

Security

We use HTTPS everywhere, httpOnly session cookies, role-based access controls, gated file downloads, encrypted transport to sub-processors, and least-privilege database access. Card data is handled entirely by Stripe. No system is perfectly secure; if you spot a vulnerability please email data@curated-chaos.co.uk.

§ 9

Automated decision-making

Our matching engine ranks creators using a transparent rule-based algorithm; a human strategist always reviews and selects the final creator. There is no fully-automated decision that produces legal effects for you.

§ 10

Changes to this policy

We may update this policy. Material changes will be notified by email or an in-product banner. The "Last updated" date at the top will always reflect the current version.

§ 11

Contact

Email data@curated-chaos.co.uk for any privacy question or request.